8 April looked like a model-release day. The more important story was that every serious agent system seemed to grow a second agent whose job was to watch the first one.
Read the full essay →6 April's strongest AI stories were not about a magical leap in intelligence. They were about sanding down rough edges until agents start to feel like dependable infrastructure.
The 5 April signal was not just bigger context windows or more tool use. It was the growing sense that agent products will be judged by how clearly they define who gets to act, where, and under what constraints.
Ai2's MolmoWeb and AWS's Nova Act point at the same lesson: browser agents become useful through data, retries, and recovery loops, not just better vibes about reasoning.
The new wave of research on hijacking AI agents is a reminder that browser systems do not get safer just because the prompt injection is hidden from the user.